Fake Hotel Complaints Deliver Blockchain C2 RAT Malware
Cofense says fake guest-complaint emails to hotel staff install EtherRAT or TONResolver, which resolve C2 from blockchain data.
On 8 October 2026, GBHackers and Cyber Security News, both citing Cofense, described phishing aimed at hotel front-desk and guest-relations staff, with one account also naming reservations teams. The lures are fabricated guest complaints; GBHackers also cites harassment claims and legal threats, while Cyber Security News describes fake negative reviews. Links lead to an archive containing a Windows LNK shortcut disguised as an image, and GBHackers adds a dummy MP4 whose changing size is meant to evade hash-based detection. Opening the shortcut fetches a legitimate Node.js runtime that launches EtherRAT or TONResolver. EtherRAT recovers a rotatable command-and-control address from an Ethereum smart contract, via a public JSON-RPC service according to one report, while TONResolver uses TON blockchain data—called wallet data in one source and a TON API dead-drop in the other—matching MITRE T1102.001. Cofense assesses with moderate confidence that this continues earlier Booking.com phishing; only the later report says those campaigns delivered PureRAT or NetSupport Manager and that generative AI may vary the email text.
- Both outlets published on 8 October 2026, citing Cofense.
- Emails target hotel front-desk and guest-relations staff; one report also names reservations staff.
- Lures are fabricated guest complaints; one source adds harassment claims and legal threats, the other fake negative reviews.
- Links deliver an archive with a Windows LNK shortcut disguised as a JPG or photo; one report also describes a dummy MP4 whose size changes to evade hash detection.
- The shortcut downloads a legitimate Node.js runtime that launches EtherRAT or TONResolver.
- EtherRAT reads an Ethereum smart contract for its C2 address (via public JSON-RPC in one account); TONResolver uses TON blockchain data, described as wallet data or a TON API dead-drop, aligned with MITRE T1102.001.
- Cofense links the activity with moderate confidence to earlier Booking.com phishing; one report says those lures delivered PureRAT or NetSupport Manager and that generative AI may vary wording.
Coverage timelineoldest first · each row is one article
- · 12h agoHackers Target Hotels With Fake Guest Complaints to Deploy Blockchain-Based RAT Malware
GBHackers· 60
Hotel staff are phished with fake guest complaints that deliver EtherRAT and TONResolver using blockchain C2 lookups.
- · 7h agoHackers Use Negative Hotel Reviews to Spread Malware That Hides C2 on Blockchain
Cyber Security News· 62
Cofense says hotel staff are phished with fake complaints that deliver EtherRAT and TONResolver using blockchain C2.